The Bureau, its statutory authority.
The Consumer Financial Protection Bureau was created by the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010, Title X, codified at 12 U.S.C. 5491. The statutory grant is broad. The Bureau regulates the offering and provision of consumer financial products and services under the Federal consumer financial laws, an enumerated list at 12 U.S.C. 5481(14) that includes the Equal Credit Opportunity Act, the Fair Credit Reporting Act, the Truth in Lending Act, the Real Estate Settlement Procedures Act, and the Consumer Financial Protection Act itself.
The Bureau has four operative levers. Rulemaking under 12 U.S.C. 5512. Supervision of covered persons under 12 U.S.C. 5514 and 5515. Enforcement under 12 U.S.C. 5564. And interpretive guidance via consumer financial protection circulars, supervisory highlights, and advisory opinions. The AI stack the Bureau has built since 2022 runs almost entirely on the fourth lever.
Circulars are not rules. The Bureau styles them as policy statements that articulate the Bureau's interpretation of how existing law applies. They impose no new obligations and require no notice-and-comment — which is exactly why the Bureau could withdraw sixteen of them in a single notice on 12 May 2025 without touching a regulation. The exposure was already there. The circular told you where it sat. Now it does not, and you read the regulation yourself.
Read the second sentence carefully, because it is narrower than a repeal. The Bureau deprioritised enforcement of the guidance. It did not and could not deprioritise ECOA, FCRA, or the statutory prohibition on unfair, deceptive, or abusive acts. The notice says plainly that "such withdrawal is not necessarily final", so a reissued circular is a live possibility. And a state attorney general enforcing Federal consumer financial law under 12 U.S.C. 5552 is not bound by the Bureau's enforcement priorities at all.
So the perimeter as of July 2026 is shorter than it was, and the distinction that survives is between regulations and guidance. What still binds: ECOA and Regulation B at 12 CFR 1002.9; the FCRA duties on users of consumer reports; the statutory prohibition at 12 U.S.C. 5531 and 5536; and the interagency Quality Control Standards for Automated Valuation Models final rule, a notice-and-comment rule published at 89 FR 64538 on 7 August 2024 and effective 1 October 2025, which the guidance withdrawal did not reach. What is withdrawn: Circular 2022-03 on adverse-action notices and complex algorithms (87 FR 35864); Circular 2022-04 on data security (87 FR 54346); Circular 2024-06 on background dossiers and algorithmic scores (89 FR 88875). Each appears by name and Federal Register citation in the withdrawal notice at 90 FR 20084.
Penalty exposure runs through 12 U.S.C. 5565. The three-tier structure is the operative ceiling. Five thousand dollars per day for any violation of Federal consumer financial law. Twenty-five thousand per day for reckless violations. One million per day for knowing violations. The amounts are adjusted annually for inflation under 28 U.S.C. 2461. Each day a noncompliant AI system processes a covered transaction is a separate violation.
ECOA adverse-action notices when AI is used.
Start here rather than with a circular, because this is the text that binds and it is untouched by the 2025 withdrawal. Two failure patterns are named in the rule itself, not in commentary: the creditor's internal standards, and a failed qualifying score. The second one is the whole AI problem in six words. A model that emits a probability and nothing else emits precisely the thing Regulation B calls insufficient.
The withdrawn Circular 2022-03 said out loud what the regulation implies — that a creditor cannot justify noncompliance on the ground that its technology is too complicated or opaque to understand. That was a useful sentence and it is no longer the Bureau's stated position. Nothing turns on losing it. The regulation never contained an opacity carve-out to begin with, so removing the interpretation that said so leaves the creditor in the same place: it must produce specific principal reasons, and the architecture of the model is the creditor's problem to solve, not the applicant's to absorb.
What follows for the engineering is unchanged, and it is worth stating without reference to any guidance document. The creditor records, per decision, the input feature vector at the level of the named variables. It records the output score or class. It records the principal reasons in plain language. The reasons are not generated retroactively. They are persisted at the moment the decision is made, in the same trace as the decision. A reason that names a variable category — length of credit history, debt-to-income ratio, recency of a derogatory item — and the direction of its effect is what satisfies "specific and indicate the principal reason(s)". If the model cannot yield that, the model is not deployable in adverse-action territory, and that conclusion comes from 1002.9(b)(2), not from a circular that has since been pulled.
A common failure pattern. The creditor uses an LLM-based agent to summarise an application package and produce a recommendation. The LLM returns natural-language output. The downstream rules engine converts the output to an approve, deny, or refer-to-human disposition. The audit trail records the LLM output. It does not record the principal-reason extraction. When the regulator asks how reason A versus reason B was selected on a given denied application, the answer must trace back to the recorded LLM context, not to a separate post-hoc reason model that was not in the decision path.
Chatbots and UDAAP exposure.
The June 2023 issue spotlight is not a circular and not a rule, and it is careful to say so. Its footnote 3 reads: "This issue spotlight is not intended to impose any obligations or define any rights and is not intended as a CFPB interpretation of any regulation or statute." So it cannot be cited as the Bureau's reading of UDAAP, and this page does not cite it that way. Structurally the document names three areas of interest, not four: § 3.1 "Limited ability to solve complex problems", § 3.2 "Hindering access to timely human intervention", and § 3.3 "Technical limitations and associated security risks", followed by § 4 "Risks associated with the integration of deficient chatbots". The four-way breakdown below is Warrant's operational mapping of those areas onto the statutes and rules that do impose obligations — the statutory routes are ours, not the Bureau's.
The supervisory implication is that a deployed financial-services chatbot is not outside the four perimeters above merely because the institution did not build the model. A bank using a third-party LLM for a customer-facing channel is the covered person for UDAAP purposes. What the spotlight actually says on liability is narrower and worth quoting rather than paraphrasing: "Like the processes they replace, chatbots must comply with all applicable federal consumer financial laws, and entities may be liable for violating those laws when they fail to do so." Treating a hallucinated answer as a deceptive practice the institution disseminated is Warrant's reading of 12 U.S.C. 5531 and 5536, not a position the Bureau has stated — the spotlight disclaims being an interpretation of any statute.
The operative engineering pattern for a defensible chatbot deployment has four parts. A factuality check on every customer-facing response, recorded in the trace. A typed escalation event whenever a session crosses a defined complexity or topic boundary. An immutable record of every complaint or dispute initiated through the channel, time-stamped and routed to the same queue as written complaints. A privacy-disclosure record per session covering what the chatbot was told and what it disclosed.
Limited English Proficiency and AI.
An earlier version of this page said it could not determine whether the Bureau's January 2021 LEP statement survived the 12 May 2025 withdrawal. That is now resolved, against the notice itself. The statement is the Statement Regarding the Provision of Financial Products and Services to Consumers With Limited English Proficiency, 86 FR 6306, published 21 January 2021. It does not appear anywhere in the withdrawal notice at 90 FR 20084: the notice's Policy Statements list runs to eight items and does not include it, and the strings "limited English", "language" and "6306" occur zero times in the notice's full text. So it was not withdrawn by that notice. One caveat the notice supplies itself: the Bureau said it "intends to continue reviewing all guidance documents to determine whether they should ultimately be retained", so this is a status as at 6 August 2026, not a permanent one.
What the statement implies for an AI agent is direct, though note it is a policy statement rather than a rule. If the institution markets a product to LEP consumers in a non-English language, the digital channel should honour the same language commitments as the human channel. An LLM-based chatbot that operates in English by default but is offered to Spanish-speaking customers must either provide a substantively equivalent Spanish experience or be explicitly scoped out of Spanish-language consumer engagement. The underlying exposure does not depend on the statement at all: a consumer-facing agent that answers less accurately in one language than another is exposed under ECOA on the credit path and under 12 U.S.C. 5531 and 5536 on the communications path.
On translation quality, the reading below is Warrant's and is marked as such rather than attributed to the Bureau. A machine-translated disclosure that materially alters the meaning of a Reg Z right or a Reg DD term sheet is a candidate deceptive act under 12 U.S.C. 5536 on the same analysis that applies to any other misdescription of a term. The institution does not get a defence on the basis that the LLM produced the translation. The institution is the discloser.
The operative engineering pattern. Record the language of every consumer interaction in the trace. Record the source language of every disclosure rendered to the consumer and any translation step applied. Record the human or model that produced the translation. Record, where applicable, the back-translation verification step.
Automated valuation models and nondiscrimination.
This is the only AI-specific final rule on the CFPB stack as of May 2026, and the CFPB is one of six issuing agencies. The Federal Reserve Board, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, the National Credit Union Administration, the Federal Housing Finance Agency, and the CFPB jointly adopted the rule under the authority of section 1125 of the Financial Institutions Reform, Recovery, and Enforcement Act, added by Dodd-Frank section 1473(q).
The rule imposes five quality-control standards on any institution that uses an AVM in connection with making a credit decision or covered securitisation determination secured by a consumer's principal dwelling. Confidence in the estimates produced. Protection against data manipulation. Avoidance of conflicts of interest. Random sample testing and reviews. And compliance with applicable nondiscrimination laws.
The fifth standard is the AI-specific one. The Bureau and its sister agencies were explicit that AVMs trained on historical valuation data risk replicating historical discrimination in property valuation. The rule does not specify a particular fairness test. It requires the institution to have policies, practices, procedures, and control systems that are designed to ensure the AVM complies with nondiscrimination laws. The Fair Housing Act, the Equal Credit Opportunity Act, and the disparate-impact doctrine in Texas Department of Housing v. Inclusive Communities apply.
The operative engineering pattern for an AVM deployment after 1 October 2025. Record, per valuation, the AVM model identifier and version. Record the input feature set and the geographic context. Record the output and any human override. Record, on a periodic basis, the disparate-impact testing results, the corrective actions taken, and the documentation of nondiscrimination compliance reviews. The record is the institution's defence in any fair-lending examination.
2024 and 2025 statements on AI in lending.
The Bureau supplemented the 2022-2023 guidance in 2024 and then withdrew the supplement. Circular 2024-06 on background dossiers and algorithmic scores in hiring, promotion, and other employment decisions was published at 89 FR 88875 on 12 November 2024 and appears as item 1 on the withdrawal list at 90 FR 20084. Its reasoning is worth knowing and is no longer citable as the Bureau's position: a score from a third-party algorithm used in an employment adverse action is a consumer report under the FCRA, and the user carries notice and accuracy obligations. Those FCRA obligations come from the statute and remain in force. The circular that mapped them onto algorithmic scores does not.
The Bureau has also issued statements on AI in mortgage origination through its supervisory highlights and through the joint regulator statement on consumer-financial-services use of AI, signed by the CFPB, the FTC, the Department of Justice Civil Rights Division, and the Equal Employment Opportunity Commission on 25 April 2023 — the Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems. It is short and operative: "Existing legal authorities apply to the use of automated systems and innovative new technologies just as they apply to other practices." That statement is not on the 90 FR 20084 withdrawal list.
Warrant does not characterise the content of individual Supervisory Highlights findings on this page. An earlier version listed AI-driven account-closure practices, debt-collection scripts and third-party adverse-action notices as 2024–2025 findings; those specifics have been removed because they were not verified against a named, dated edition, and the honest form of the point does not need them. The durable observation stands on the instruments themselves: ECOA, FCRA and the UDAAP prohibition ask for the same artefacts they have always asked for, and the fact that an artefact was produced by an AI system is not a defence — it is a description of how the violation occurred.
CFPB, the Fair Housing Act, and the UDAAP perimeter.
The CFPB's AI guidance does not operate in isolation. Three other statutory perimeters attach to the same fact pattern. The Fair Housing Act, 42 U.S.C. 3601 and following, prohibits discrimination in residential real-estate transactions. ECOA, codified at 15 U.S.C. 1691 and implemented in Regulation B at 12 CFR Part 1002, prohibits discrimination in any aspect of a credit transaction. UDAAP, codified at 12 U.S.C. 5531 and 5536, prohibits unfair, deceptive, or abusive acts and practices.
The cross-reference web matters because the same AI deployment routinely touches all three. An AI mortgage-underwriting agent is subject to ECOA on the credit decision, the Fair Housing Act on the housing element, and UDAAP on every customer-facing communication. A finding under one statute does not preclude findings under the other two. The Department of Justice and HUD enforce the Fair Housing Act in parallel. State attorneys general enforce ECOA and UDAAP under 12 U.S.C. 5552.
The argument that AI opacity is a defence does not survive any of the three perimeters. Regulation B forecloses it at 12 CFR 1002.9(b)(2), which requires specific principal reasons and names a failed qualifying score as insufficient — no guidance document is needed to reach that. The Fair Housing Act's disparate-impact doctrine, affirmed by the Supreme Court in Texas Department of Housing v. Inclusive Communities Project (2015), does not require proof of intent; it requires proof that a facially neutral practice has a disproportionate adverse effect, and an opaque model cannot rebut the showing. UDAAP requires no scienter for the unfair or deceptive prongs.
The same chain runs through state actors, and the safest way to say so is without a roster. Several states have layered automated-decision-system or AI rules over the Federal floor, and the detail — which statute, which effective date, which sections — moves fast enough that Warrant states it only where it has checked the enacted instrument. For a New York-regulated institution the concrete overlay is 23 NYCRR Part 500, read at the Part 500 mapping. The Federal floor is not a ceiling, but a claim about any particular state's rule belongs on a page where that state's instrument has been read.
Where Warrant maps CFPB obligations.
The mapping below is by-action, not by-trace, because each obligation attaches at the decision moment, not at the session moment. Read the FIELD column literally: it names properties of the signed warrant-v1 package as defined in api/spec/warrant-v1-evidence.schema.json, which sets additionalProperties: false at the root and on every action and authorization row — so a name absent from the schema is prohibited, not merely unimplemented. Four of the five rows below have no field. Consumer-protection law asks for artefacts the institution produces: an adverse-action notice, an accuracy control on customer-facing output, a language-access decision, a valuation-model quality-control record. Warrant evidences the decision those artefacts are owed for; it does not carry the artefacts, and only the per-decision rationale row maps to a field that exists.
warrant-v1 has no adverse-action-reasons field; the statement of specific reasons is the creditor's notice, and no property of the package holds its text. What the package carries for this row is obligations.<action_id>[].id with .compliance and .evidence — whether the reasons obligation was met for that action, and the assessment that reached it.
authorizations[].justification, one row per action_id. Stated precisely, because the distinction is the whole point of the rule: the decision-time rationale is whatever the ingested trace's own step outputs recorded, and authorizations[].justification is Warrant's assessment of that action, produced at attestation. The package binds the two together; it does not manufacture a contemporaneous reason where the trace carried none.
warrant-v1 has no factuality field — no checker, no score, no threshold — so a chatbot's accuracy is not something the package attests. What it does carry per action is authorizations[].justification and .confidence, which record Warrant's own confidence in its authorization judgement, not the agent's truthfulness.
warrant-v1 has no language field, and it has no metadata root at all — the root property list is closed, so a metadata.* path can never appear on a package. classification.jurisdictions records where the decision sits, which is not the language it was delivered in.
warrant-v1 identifies no deployer model and holds no disparate-impact review; the periodic record is an institutional artefact, not a per-decision one. The receipt's pipeline_models names the models Warrant's own assessment pipeline ran, which is a different thing and should not be read as the valuation model under review.
Questions a compliance officer asks first.
Read the source directly.
- Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal · 90 FR 20084 · 12 May 2025 · the notice that withdrew Circulars 2022-03, 2022-04 and 2024-06 (Federal Register full text)
- 12 CFR 1002.9 · Regulation B · notifications, including the specific-reasons requirement at (b)(2) (eCFR, current)
- CFPB Issue Spotlight · Chatbots in consumer finance · June 2023
- CFPB Consumer Financial Protection Circulars · index
- CFPB Supervisory Highlights · index
- Federal Register · Quality Control Standards for Automated Valuation Models · 7 August 2024
- 12 CFR § 1002.9 · ECOA Regulation B · notifications
- 12 U.S.C. § 5565 · CFPB civil penalty tiers
- Warrant regulator index · the regimes we map evidence against
Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. Corrected 28 July 2026. The verbatim quotation of 12 CFR 1002.9(b)(2) is taken from the eCFR rendering of title 12 as at 1 July 2026. The verbatim quotations of the withdrawal notice are taken from the Federal Register full text of 90 FR 20084, published 12 May 2025, in which Circular 2024-06 appears as item 1 (89 FR 88875), Circular 2022-04 as item 13 (87 FR 54346), and Circular 2022-03 as item 14 (87 FR 35864) of the Other Guidance list. The AVM final rule is 89 FR 64538 of 7 August 2024, effective 1 October 2025. An earlier version of this page presented the three withdrawn circulars as current authority and quoted 2022-03 in the present tense; that was wrong on the date and is corrected here.